Impact
Unsloth Zoo versions prior to 2026.8.14, as included in Unsloth releases 2025.9.9 through 2026.8.19, contain a code injection flaw. The get_transformers_model_type() function collects model_type values from nested model configurations without restricting the character set, allowing an attacker to place a newline in a nested model_type. The newline ends the generated import statement and enables arbitrary Python code to be executed by exec() during the compile step, giving remote code execution as the user that loads the model for training or inference.
Affected Systems
Products affected are unslothai Unsloht and unslothai Unsloht Zoo. Version ranges impacted include Unsloht Zoo 2025.9.9 up through 2026.8.13 (inclusive) and Unsloht 2025.9.9 through 2026.8.19. Any instance of these releases that loads models from untrusted sources is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalogue. An attacker who can supply a malicious config.json to the model‑loading API can trigger remote code execution. The likely attack vector is via a compromised model file stored in a public or unprotected repository and then loaded by a system using Unsloht or Unsloht Zoo. Because the flaw is in the compile path, environments that auto‑load models for inference or training without additional validation are exposed.
OpenCVE Enrichment